Who we help
Built for organizations of 25 to 250 people.
actually. provides independent IT audits and advisory to organizations that rely heavily on technology but have no independent executive reviewing risk, performance and strategy.

The profile
Our clients, typically.
Read the engagements with a Canadian engineering consultancy and a Canadian manufacturer.
Financial Services
Financial Services companies operate in fast-moving environments where downtime, payment fraud, compromised accounts and lost project information can create immediate financial consequences.
We help review:

Law Firms and Professional Services
Professional-services firms hold confidential information, rely heavily on email and documents, and face growing client expectations around cybersecurity.
We help review:

Associations and Unions
Associations and unions manage member information, financial records, communications, benefits information and sensitive internal documents.
We help leadership understand:

Owner-Managed Businesses
Owners often receive technology information through a single provider or internal employee. This can make it difficult to evaluate performance objectively.
We provide the owner with an independent view of:

Businesses in Transition
Independent review is especially valuable during moments of significant change, when the technology environment is most exposed.
Independent review is especially valuable during:

Find your starting point
What decision is in front of you?
The question sets the scope. Your internal team or IT provider continues to operate your systems.
A contract is coming up for renewal.
Compare the commitments you bought with the evidence of service delivered before agreeing to another term.
Check your renewal evidenceLeadership needs security evidence.
Examine which controls are in scope, what supports the provider's statements and which questions remain unverified.
Explore an independent cybersecurity auditThe reports do not answer your questions.
Bring technology, provider performance, spending and risk into one review that explains findings in business terms.
Explore the Actually ReviewYour organization does not need to be technical.
It needs technology that is accountable to the business.
Keep reading
Where to go next.
The review, ongoing oversight, and leadership
Three ways to work with an independent firm, from one report to a standing seat at the table.
Case studiesTwo reviews, both kept their provider
What an independent review found in practice, and why neither business changed provider afterwards.
Evaluating your providerHow to evaluate the managed IT provider you already have.
Compare agreed services with records, reported claims and unresolved questions.